FlawAtlas
Search the atlas
OPENSUSE-SU-2026:21151-1 Not scored

Security update for warewulf4

This update for warewulf4 fixes the following issues: Changes in warewulf4: - updated go-jose to fix CVE-2026-34986 (bsc#1262810) - chi is fixed in the upstream project - updating to v4.7.0 with following security fixes * fixed CVE-2026-39821 (bsc#1266483) * fixed CVE-2026-33814 (bsc#1265653) - v4.7.0 with significant changes relative to the v4.6.x series which are: * New wwctl unset command * Refactored server routes (URLs) * New /files/ route for serving individual files and templates * Server TLS support * Removed support for fetching individual overlays and individual files from overlays * Fixed whitespace handling around template functions * Security fixes, including updated Go and library versions - changes from v4.6.5: * new wwctl overlay info command * fixed wwctl image import --update option * cross-arch support for wwclient * improved IPv6 support * improved support for bonded interfaces * renamed debian.interfaces overlay to ifupdown * new systemd-networkd overlay * warewulf-dracut fixes, including "provision-to-disk" fixes - remove slurm-overlay package - fix CVE-2025-69725 (bsc#1258511) by updating chi - updated to v4.6.5 with following changes: * new wwctl overlay info command * fixed wwctl image import --update option (bsc#1254470) * cross-arch support for wwclient * improved IPv6 support * improved support for bonded interfaces * renamed debian.interfaces overlay to ifupdown * new systemd-networkd overlay * warewulf-dracut fixes, including "provision-to-disk" fixes - default to dnsmasq instead of dhcpd and tftp

Exploit probability Not scored
Published June 23, 2026
Required by Not available
Last source change June 30, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 16.0 warewulf4

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2026:21151-1

This update for warewulf4 fixes the following issues: Changes in warewulf4: - updated go-jose to fix CVE-2026-34986 (bsc#1262810) - chi is fixed in the upstream project - updating to v4.7.0 with following security fixes * fixed CVE-2026-39821 (bsc#1266483) * fixed CVE-2026-33814 (bsc#1265653) - v4.7.0 with significant changes relative to the v4.6.x series which are: * New wwctl unset command * Refactored server routes (URLs) * New /files/ route for serving individual files and templates * Server TLS support * Removed support for fetching individual overlays and individual files from overlays * Fixed whitespace handling around template functions * Security fixes, including updated Go and library versions - changes from v4.6.5: * new wwctl overlay info command * fixed wwctl image import --update option * cross-arch support for wwclient * improved IPv6 support * improved support for bonded interfaces * renamed debian.interfaces overlay to ifupdown * new systemd-networkd overlay * warewulf-dracut fixes, including "provision-to-disk" fixes - remove slurm-overlay package - fix CVE-2025-69725 (bsc#1258511) by updating chi - updated to v4.6.5 with following changes: * new wwctl overlay info command * fixed wwctl image import --update option (bsc#1254470) * cross-arch support for wwclient * improved IPv6 support * improved support for bonded interfaces * renamed debian.interfaces overlay to ifupdown * new systemd-networkd overlay * warewulf-dracut fixes, including "provision-to-disk" fixes - default to dnsmasq instead of dhcpd and tftp

View original source

05 / REFERENCES

Further evidence